[codicts-css-switcher id=”346″]

Global Law Experts Logo
ghana establishes a virtual

Talk with Our Expert

Legal professional smiling at desk with a globe and legal-themed decor in modern office setting.

Jonathon Richards

Global Law Experts

Lead Enquiries Qualification
Delete Article

Ghana Establishes a Virtual Assets Regulatory Committee Before Issuing Any VASP Licence

By Global Law Experts
– posted 51 minutes ago

Who this is for: fintech founders, compliance officers, in-house counsel, external counsel advising virtual asset service providers, investors and compliance consultants operating in or entering the Ghanaian market.

Quick take: Ghana is building a coordinated, multi-agency structure to centralise regulatory coordination for virtual assets before any licences are granted. The immediate priorities for firms are anti-money laundering (AML) preparedness, beneficial ownership verification and technical security. The recommended action is to begin remediation now and prepare robust documentation for future licence applications.

Contributor: Global Law Experts editorial team, with input from a Ghana-based financial regulation specialist within the GLE network. The practical guidance below reflects a synthesis of official regulator roles and standard AML and VASP compliance practice, and should be confirmed against current official publications before it is relied upon.

Executive summary, what the coordinating structure is and why it matters

Ghana is moving to bring order and inter-institutional discipline to the supervision of digital assets before virtual asset service provider (VASP) licences are issued. The Bank of Ghana has publicly indicated its intention to bring virtual assets within a formal regulatory perimeter and to work with other public institutions to do so. The relevant financial, security and policy institutions are being drawn together under a coordinating approach, signalling that Ghana intends to build its regulatory architecture first and license operators second. The institutions most relevant to this work include the Bank of Ghana, the Securities and Exchange Commission, the Ministry of Finance, the Cyber Security Authority and the Financial Intelligence Centre.

For businesses, the sequence matters as much as the substance. By assembling regulatory coordination before opening a licensing window, the authorities are effectively telling the market that AML controls, beneficial ownership transparency and cybersecurity resilience will be baked into the eventual licensing criteria rather than bolted on afterwards. Firms already offering crypto-related services face the most acute exposure, because supervision is being formalised around them. The practical headline for every operator and adviser is the same: prepare documentation, close compliance gaps and monitor each agency’s publications closely, because the standards that will govern licensing are being shaped now.

Background, Ghana’s approach to virtual assets to date

Ghana’s financial regulators have engaged cautiously but consistently with the rise of digital assets. The Bank of Ghana has historically approached cryptocurrencies from a payments and financial-stability perspective, mindful of consumer protection and the integrity of the national payment system, and has previously cautioned the public that cryptocurrencies were not recognised as legal tender or licensed for use in Ghana. The Securities and Exchange Commission has addressed the investment-product dimension of tokens and trading platforms, while the Financial Intelligence Centre has carried the AML and counter-terrorist-financing (CFT) mandate across the wider financial sector. The Ministry of Finance sits above these institutions on questions of policy direction and legislative reform.

The move toward coordinated, whole-of-government supervision reflects a maturing of that engagement, a shift from isolated statements by individual regulators toward a coherent framework. This matters because virtual assets do not respect institutional boundaries: a single crypto exchange simultaneously raises payments questions, securities questions, AML questions and cybersecurity questions. A coordinating mechanism is the means by which those overlapping mandates can be reconciled into a coherent rulebook.

Key statutes and regulatory frameworks affecting VASPs

Several existing legal frameworks will underpin this work even before bespoke virtual-asset legislation is finalised:

  • Anti-money laundering legislation. Ghana’s AML statutory framework, including the Anti-Money Laundering Act, 2020 (Act 1044), and related regulations, administered in practice with the Financial Intelligence Centre, imposes customer due diligence, record-keeping and suspicious transaction reporting obligations on accountable institutions. VASPs should expect to be treated as accountable institutions for these purposes.
  • Securities and capital-markets law. The mandate of the Securities and Exchange Commission under the Securities Industry Act, 2016 (Act 929) extends to investment products, and token offerings or trading platforms may fall within its remit.
  • Payments and central-banking law. The Bank of Ghana’s authority over payment systems and financial stability, grounded in the Bank of Ghana Act, 2002 (Act 612, as amended) and the Payment Systems and Services Act, 2019 (Act 987), provides a basis for oversight of virtual-asset activity that touches on payments.
  • Cybersecurity law. The Cyber Security Authority’s statutory role under the Cybersecurity Act, 2020 (Act 1038) gives it standing to set technical and resilience expectations for digital service providers.

Firms should treat the Parliament of Ghana and the government gazette as the authoritative source for the precise Acts and any forthcoming virtual-asset regulations, and should confirm exact provisions and current amendments before relying on them.

Which agencies are involved, expected roles

The strength of a coordinated approach lies in the complementary mandates of the institutions involved. Understanding what each agency brings is essential to anticipating how licensing conditions and ongoing supervision will be shaped. Coordinating monetary, market, policy, security and financial-intelligence expertise in a single forum allows overlapping concerns to be reconciled.

  • Bank of Ghana. As the central bank, it leads on financial stability, payment systems and monetary integrity, and has taken a leading role in signalling a forthcoming regulatory framework for virtual assets.
  • Securities and Exchange Commission. The capital-markets regulator addresses market conduct, investor protection and the oversight of trading, custody and exchange activity that may resemble securities dealing.
  • Ministry of Finance. The policy and fiscal arm responsible for legislative direction, fiscal treatment of virtual assets and the broader economic-policy framework.
  • Cyber Security Authority. The national body for cyber resilience, responsible for technical security standards, incident response and the protection of critical digital infrastructure.
  • Financial Intelligence Centre. The AML and CFT financial-intelligence body and the recipient of suspicious transaction reports, providing the financial-intelligence backbone of this work.

Chairing and decision-making, role of the Bank of Ghana

The Bank of Ghana has positioned itself at the centre of coordination on virtual assets. In practice, leading a multi-agency effort usually means responsibility for convening meetings, setting agendas, arbitrating between differing institutional positions and driving the group toward consensus deliverables. Because the Bank of Ghana already holds systemic financial-stability responsibilities, its leadership signals that stability and payment-system integrity will be treated as first-order concerns in the eventual framework.

Expected work programme and deliverables

Industry observers expect coordination of this kind to work toward a defined set of deliverables: a licensing framework and criteria, standard operating procedures for application assessment, AML supervisory expectations and cybersecurity standards. The likely practical effect is a phased publication of guidance, with foundational AML and cybersecurity requirements emerging ahead of, or alongside, the opening of any licensing window. Firms should watch for gazetted notices and regulator publications as the concrete markers of progress.

Remit, licensing, AML and cybersecurity supervision

The remit is best understood as a bridge between policy-making and supervision. Establishing coordination before licensing suggests the first task is to design the rules, not to police individual firms. Its likely functions include drafting licensing criteria, harmonising AML and CFT supervisory expectations, defining technical and cybersecurity requirements, and coordinating enforcement and investigative activity across agencies.

What a coordinating body can (and cannot) do legally

A coordinating mechanism is a means of alignment; it does not ordinarily replace the statutory powers of its constituent members. Each agency retains its own legal authority, the Financial Intelligence Centre continues to receive suspicious transaction reports, the Securities and Exchange Commission continues to regulate market conduct, and the Bank of Ghana continues to oversee payment systems. What coordination adds is shared standards, joint positions and reduced duplication. It cannot, on its own, create binding law; new binding obligations flow from statutes, regulations or gazetted notices issued through the proper legal channels. Firms should therefore distinguish between policy signals and legally enforceable requirements once they are published.

How the remit affects licence sequencing

Because standard-setting precedes licensing, applicants have a valuable window. The remit implies that AML, beneficial ownership and cybersecurity requirements will be substantially defined before applications are assessed. Firms that build their governance and controls to anticipated standards now will be better placed when the licensing window opens, while those that wait for final rules risk a compressed and pressured preparation period.

AML/CFT expectations for VASPs, practical checklist

AML and CFT compliance will sit at the heart of Ghana’s virtual-asset regime. The Financial Intelligence Centre’s involvement makes clear that financial-crime controls are not an afterthought. The following checklist reflects standard AML and VASP practice and should be treated as a preparatory baseline pending final Ghanaian guidance.

  • Customer due diligence (CDD). Verify customer identity at onboarding using reliable, independent documentation and maintain up-to-date records.
  • Enhanced due diligence (EDD). Apply additional scrutiny to politically exposed persons (PEPs), high-risk jurisdictions and unusually complex or large transactions.
  • Transaction monitoring. Deploy systems to detect anomalous patterns, structuring and behaviour inconsistent with a customer’s declared profile.
  • Sanctions screening. Screen customers and counterparties against applicable sanctions lists on onboarding and on an ongoing basis.
  • Suspicious transaction reporting (STR). Establish clear internal escalation and reporting workflows so that suspicious activity is reported promptly to the Financial Intelligence Centre.
  • Compliance officer. Appoint a qualified compliance officer with authority and independence to oversee the AML programme.
  • Record retention. Retain customer records and transaction data for the periods required by law.

Beneficial ownership, standards and documentary evidence

Beneficial ownership (BO) transparency is a recurring priority in virtual-asset supervision, and it is likely to feature prominently in Ghana’s framework. A beneficial owner is the natural person who ultimately owns or controls a customer or the entity applying for a licence. Applicants and operators should:

  • Maintain a documented BO register identifying all natural persons holding significant ownership or control.
  • Collect supporting documents such as certified identity documents, shareholding structures, and evidence of control arrangements.
  • Verify ownership independently rather than relying solely on self-declaration, and update records when ownership changes.
  • Unwind complex or opaque ownership chains to identify the ultimate controlling persons.

Source-of-funds and source-of-wealth, what to collect

Source-of-funds (SOF) and source-of-wealth diligence establishes that the money moving through a VASP has a legitimate origin. Firms should collect documentary evidence, such as salary records, business income, sale proceeds or investment returns, and corroborate it against the customer’s overall profile. Risk indicators warranting deeper investigation include mismatches between declared income and transaction volumes, funds routed through high-risk jurisdictions, and reluctance to provide documentation. For higher-risk customers, source-of-wealth checks should extend beyond the immediate transaction to the customer’s broader financial background.

Record-keeping and reporting timelines

Robust record-keeping underpins every other AML control. Firms should retain CDD documentation, transaction records and STR filings in a form that can be produced to supervisors on request, and for the retention periods set by Ghanaian law. Reporting timelines for suspicious activity should be built into internal procedures so that filings to the Financial Intelligence Centre are made without undue delay once suspicion arises.

Multi-agency supervision in practice, accountability and escalation

The operational question every firm asks is deceptively simple: when something goes wrong, who is in charge? Under a multi-agency model, responsibilities are allocated by function. The Bank of Ghana is likely to lead on systemic stability and payment-system integrity; the Securities and Exchange Commission on market conduct and the licensing of trading platforms; the Financial Intelligence Centre on AML analysis and STR intelligence; the Cyber Security Authority on cyber incidents and technical resilience; and the Ministry of Finance on policy and statutory change. Memoranda of understanding, joint inspections and coordinated enforcement are the tools that hold such a structure together.

Practical scenario: a suspicious flow detected on an exchange

Consider a suspicious transaction pattern detected on a licensed exchange. The exchange’s compliance function files a suspicious transaction report with the Financial Intelligence Centre, which analyses the intelligence. If the pattern suggests market abuse, the Securities and Exchange Commission may take the lead on conduct issues; if it involves a security breach or compromised systems, the Cyber Security Authority engages on the technical side; and if it raises payment-system or stability concerns, the Bank of Ghana is drawn in. The value of coordination is that these agencies act in concert rather than in isolation, escalating through agreed channels rather than duplicating effort.

Feature Single regulator model Ghana’s expected multi-agency coordination
Primary focus Licensing and supervision consolidated Function-specific agencies: stability, markets, AML, cyber, policy
Speed of decision-making Potentially faster single-point Requires coordination; risk of slower consensus
Technical depth May lack specialist inputs Access to domain expertise (FIC, CSA, SEC, BoG)
Regulatory certainty Single rulebook possible Need for MoUs and clarity to avoid overlap
Enforcement Centralised enforcement Joint investigations, role-based enforcement

Sequencing risk and remedies for existing operators

Firms already offering crypto services in Ghana carry the greatest exposure. Because supervisory standards are being set before licences are granted, existing operators occupy a transitional grey zone: they are operating while the supervisory framework crystallises around them, and cryptocurrencies are not currently recognised as legal tender in Ghana. The risks include enforcement action, financial penalties, reputational damage and mandatory remediation. The prudent response is to reduce that exposure proactively rather than wait to be examined.

Checklist for operators currently active in Ghana

  • Conduct a formal compliance gap assessment against anticipated AML, beneficial ownership and cybersecurity standards.
  • Build or verify a beneficial ownership register for the business and its customers.
  • Implement or upgrade transaction monitoring and STR reporting workflows to the Financial Intelligence Centre.
  • Document governance, appoint a compliance officer and evidence fit-and-proper standards for senior management.
  • Preserve audit trails and records so that a supervisor’s information request can be met quickly.

When to seek voluntary disclosure or remediation

Where a gap assessment reveals material historical non-compliance, firms should take legal advice on whether voluntary engagement with regulators is appropriate. Early, good-faith disclosure and a credible remediation plan can, in many regulatory environments, mitigate enforcement outcomes. The decision is fact-specific and carries its own risks, so it should be made with counsel and with a clear remediation timeline in place.

How to prepare a VASP licence application, documentation and readiness

Application readiness is where the abstract becomes concrete. Even though final licensing criteria are still being shaped, the core documentation that any credible VASP application will require is predictable, and firms can assemble it now.

Template checklist of application attachments

  • Governance. A detailed business plan, corporate structure, board composition, and fit-and-proper evidence for directors and senior managers.
  • AML and CFT. Written AML and CFT policies, CDD and EDD procedures, a beneficial ownership register, source-of-funds procedures and a compliance officer appointment.
  • Technical and cybersecurity. Cybersecurity controls, an incident response plan, resilience testing evidence and data-protection arrangements aligned to Cyber Security Authority expectations.
  • Financial. Audited or projected financial statements, capital adequacy evidence and audit trails demonstrating operational integrity.

Applicants should treat the eventual official application forms and guidance, published by the responsible agencies, as authoritative, and should tailor their documentation to the specific conditions those agencies set.

Practical next steps and recommended timeline for firms and advisers

The single most useful thing any firm can do is convert this development into a structured programme of work. Because supervisory standards are being set ahead of licensing, there is a genuine opportunity to prepare methodically rather than react under pressure.

Sample action plan

  • First 90 days. Complete a risk assessment and compliance gap analysis; build the beneficial ownership register; appoint or confirm a compliance officer; and draft core AML and CFT policies.
  • By 180 days. Remediate technical and cybersecurity gaps, implement transaction monitoring and STR workflows, and commission an internal or external compliance audit.
  • By 365 days. Finalise the licence application dossier, engage constructively with the relevant regulators and align internal controls to any published standards.

Conclusion, risks and opportunities

Ghana’s decision to establish supervisory coordination before issuing any VASP licence is a clear signal that compliance, not speed, will define market entry. For firms that act now, building beneficial ownership registers, tightening AML controls and strengthening cybersecurity, the sequencing is an opportunity to prepare properly. For those that wait, it is a source of avoidable risk. The prudent course is proactive: assess gaps, remediate, document thoroughly, take specialist legal advice and monitor each agency’s announcements closely, because the standards that will govern licensing are being written now.

Sources

  1. Bank of Ghana
  2. Securities and Exchange Commission Ghana
  3. Ministry of Finance, Ghana
  4. Financial Intelligence Centre, Ghana
  5. Cyber Security Authority, Ghana
  6. Parliament of the Republic of Ghana
  7. International Monetary Fund, Ghana country page
  8. GIABA, Inter-Governmental Action Group against Money Laundering in West Africa

FAQs

Which agencies are expected to be involved in Ghana's virtual asset supervision?
The institutions most relevant to this work are the Bank of Ghana, the Securities and Exchange Commission, the Ministry of Finance, the Cyber Security Authority and the Financial Intelligence Centre. Together they cover financial stability, market conduct, policy, cybersecurity and AML supervision. Firms should confirm the composition and mandate of any formal committee against official announcements.
Because standards are being set first, the final licensing model, single or activity-based, will be specified in regulator guidance. Applicants should prepare for activity-specific conditions alongside comprehensive AML and cybersecurity requirements.
Implement robust customer due diligence and enhanced due diligence, maintain a beneficial ownership register, conduct source-of-funds checks, deploy transaction monitoring, appoint a compliance officer and establish suspicious transaction reporting workflows to the Financial Intelligence Centre.
Risks include enforcement action, fines, reputational damage and forced remediation. Cryptocurrencies are not currently recognised as legal tender in Ghana. Firms should conduct a compliance gap assessment and consider, with counsel, whether voluntary disclosure to regulators is appropriate.
The Cyber Security Authority is expected to be involved, so VASPs should be prepared to meet its required technical controls, including incident response, data protection and resilience testing, once the applicable standards are published.
Official guidance and application materials will be published by the responsible agencies, the Bank of Ghana, the Securities and Exchange Commission, the Financial Intelligence Centre and the Cyber Security Authority. Firms should monitor these agencies’ websites and the government gazette for official notices.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Ghana Establishes a Virtual Assets Regulatory Committee Before Issuing Any VASP Licence

Send welcome message

Custom Message